@Ashlee Sims, Thanks for posting in Q&A. From your description I know you are doing GPO enrollments. Some devices can enroll successfully. But some can't. For the affected device, from the information you provided, it shows the issue is that Microsoft Entra Hybrid joined is failed. The AzureADjoined and AzureAdPrt are all NO.
In general, to enroll devices via GPO enrollment, the devices need to be Microsoft Entra hybrid Joined successfully firstly which means the AzureADjoined, Domainjoined and AzureAdPrt are all Yes.
In the Diagnostic Data, it says the issue occurs in Discover phase. and the error message is "UPN suffix parameter contains spaces:". Please double confirm with the user's UPN to see if any space exists. If yes, remove it in AD and sync again to see if it can work.
Meanwhile, here is a troubleshooting link for Microsoft Entra hybrid join. You can read it as a reference.
https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-hybrid-join-windows-current
In addition, to remove previous enrollment information, please also clean the data under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollment.
Please try the above suggestion and if there's any update, feel free to let us know.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.